First published: Mon Dec 09 2024(Updated: )
Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
miniOrange Social Login for WordPress | <=7.6.0 | |
WordPress Social Login and Register | <=7.6.0 |
Update the WordPress WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin to the latest available version (at least 7.6.1).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25455 is classified as a Missing Authorization vulnerability, which can lead to unauthorized access due to incorrectly configured access control security levels.
To fix CVE-2023-25455, update the miniOrange WordPress Social Login and Register plugin to the latest version that addresses this vulnerability.
CVE-2023-25455 affects versions of miniOrange WordPress Social Login and Register up to and including 7.6.0.
The impact of CVE-2023-25455 may allow attackers to exploit the missing authorization to gain access to sensitive functionalities.
Yes, CVE-2023-25455 is expected to be addressed in future releases of the miniOrange WordPress Social Login and Register plugin.